8.8
CVE-2023-2628
- EPSS 0.14%
- Veröffentlicht 27.06.2023 14:15:11
- Zuletzt bearbeitet 21.11.2024 07:58:57
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
KiviCare – Clinic & Patient Management System (EHR) <= 3.2.0 - Cross-Site Request Forgery
The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)
Mögliche Gegenmaßnahme
KiviCare – Clinic & Patient Management System (EHR): Update to version 3.2.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
KiviCare – Clinic & Patient Management System (EHR)
Version
*-3.2.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.352 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|